Your data stays tied to your workspace
Last updated August 12, 2026
Loresta is operated by Michael Ngo, a sole proprietor, who is responsible for the personal data processed through the service.
What we collect
We collect account details, approved creator profile information, connected social account identifiers, inbound conversation content, operational receipts, security events, and first-party activation events needed to run and improve Loresta. Activation events record actions such as viewing pricing or connecting a provider without storing the text of your messages.
Attribution and experiments
We use a first-party random visitor identifier to understand which landing page, campaign, referring domain, or page experiment led to signup, connection, activation, and purchase. We store only approved campaign parameters and the referring domain, not full referring URLs, message content, or arbitrary query parameters. The browser identifier and unattached attribution record expire after 90 days. Known bots and configured internal traffic are excluded from conversion reporting.
How we use it
We use data to provide the service, enforce your automation rules, secure your account, troubleshoot delivery, process billing, alert you to conversations that need a human, and show workspace results. We do not sell personal data or use private conversation content for advertising.
Reply previews and voice learning
Public reply previews are processed to return the sample you request and are not saved by Loresta. If you opt into voice learning, Loresta temporarily reads replies you authored through a connected account, filters sensitive data, and saves a reusable style summary rather than the raw reply history. You can turn voice learning off and clear the learned summary.
Service providers
We use infrastructure, email, billing, AI, and connected social providers only to operate approved Loresta features. Those providers process data under their own terms and the instructions needed to deliver the service.
Connected platforms
Social access is granted through OAuth. Tokens are encrypted at rest, limited to supported DM actions, and removed from active use when you disconnect an account. Provider data remains subject to each connected platform's policies.
Retention and control
Conversation content follows the retention period configured for your workspace, with a 90-day default. The dashboard lets workspace owners export records, disconnect accounts, and submit a verified deletion request. Confirmed deletion removes workspace records and stored media, subject to limited security, legal, or billing records we must retain.
Security and access
We use workspace isolation, encrypted credentials, short-lived sign-in links, role checks, CSRF protection, audit records, and restricted administrative operations. No internet service can promise absolute security.
Contact
Questions or privacy requests can be sent to privacy@loresta.co.